Popup Banner

Privacy Policy

Effective Date: 15/06/2026

Last Updated: 25/09/2026

This Privacy Policy explains how ProfitAcc 365 (“we”, “us”, “our”, or “Company”) handles information in connection with the ProfitAcc 365 mobile application (“App”).

ProfitAcc 365 is a business-to-business (B2B) mobile application designed to provide authorised employees and agents of client organisations with mobile access to selected ERP and accounting information and approval functions.

By using the App, you acknowledge that you have read and understood this Privacy Policy.

1. About ProfitAcc 365

ProfitAcc 365 is a mobile client for the Profit ACC365 Cloud ERP & Accounting platform.

The App does not provide consumer registration or guest access. Users are generally employees or authorised representatives of a client organisation and receive their login credentials from that organisation.

The App connects directly to the GraphQL server configured by the relevant client organisation. The organisation controls the business data available through that server.

The App does not operate an independent database containing the organisation’s ERP business records.

2. Information We Collect

The information handled by the App can be divided into two categories:

A. Information relating to the App user

Depending on the configuration of the client organisation, the App may process:

  • Email address used for authentication.
  • Password used for authentication.
  • User ID.
  • User name.
  • User role.
  • Department selection, where department-wise login is enabled.
  • Authentication access and refresh tokens.
  • App preferences such as Light/Dark theme selection.
  • Certain locally stored report-filter preferences.

Passwords are used for authentication and are not stored locally by the App.

Authentication tokens and certain account/session information are stored using the device’s secure storage facilities.

B. Business and personal information displayed from the client organisation’s server

The App may display information that already exists on the client organisation’s ERP server.

Depending on the organisation’s configuration and the user’s permissions, this may include:

  • Customer and supplier names.
  • Customer and supplier addresses.
  • Phone numbers and email addresses.
  • Tax registration information.
  • Credit limits and payment terms.
  • Customer and supplier account information.
  • Bank account and banking information.
  • Cheque information.
  • Purchase order information.
  • Quotation and sales information.
  • Financial balances and transaction information.
  • Employee names, employee codes and designations.
  • Employee certificate and document information.
  • Employee document images or scans.
  • Vehicle registration numbers and chassis numbers where applicable.
  • Approval information, including the name or ID of an employee who approved or rejected a transaction.
  • Salesperson information.

This information belongs to and is controlled by the relevant client organisation. The App displays such information according to the organisation’s server configuration and the permissions assigned to the user.

3. How We Use Information

Information handled through the App may be used to:

  • Authenticate authorised users.
  • Maintain user sessions.
  • Refresh authentication sessions.
  • Determine the user’s permissions.
  • Display ERP reports and information.
  • Display customer, supplier and employee information authorised by the organisation.
  • Display financial and accounting information authorised by the organisation.
  • Allow authorised users to approve or reject Purchase Orders.
  • Allow authorised users to approve or reject Quotation Sales.
  • Remember selected App preferences.
  • Provide the functionality of the App.

The App does not independently determine which business records a user is authorised to access. Access is controlled through the client organisation’s server-side permissions.

4. Client Organisation’s Responsibility

Each client organisation operates or controls the ERP/GraphQL server to which its users connect.

The client organisation is responsible for:

  • Creating and managing user accounts.
  • Assigning user permissions.
  • Determining what business information users can access.
  • Maintaining the accuracy of its business information.
  • Determining applicable data retention periods.
  • Managing its customer, supplier and employee information.
  • Managing account suspension and removal.
  • Handling data-subject requests relating to information controlled by the organisation.

Where the App displays business or personal information from a client organisation’s server, the relevant organisation generally remains responsible for that information and its processing.

5. Information Stored on Your Device

The App uses secure device storage for certain information required for its operation.

This may include:

  • Configured GraphQL server address.
  • Authentication access token.
  • Authentication refresh token.
  • User ID.
  • User name.
  • User role.
  • Department ID, where applicable.
  • Theme preference.
  • Selected report-filter preferences.

Authentication/session information is cleared when the user signs out.

Certain application preferences, such as the configured server information, theme preference and report-filter preferences, may remain stored after sign-out.

The App does not maintain a local database of the organisation’s ERP business records.

6. Information We Do Not Collect

Based on the current App functionality, the App does not collect:

  • GPS or precise location information.
  • General device location information.
  • Contacts.
  • Microphone recordings.
  • Biometric information.
  • Advertising identifiers.
  • User tracking information.
  • Payment card information.
  • Photos captured by the user.
  • Camera images captured by the user.
  • Push-notification tokens.
  • Analytics events.
  • Crash-reporting or diagnostic information through a third-party analytics/crash SDK.

The App also does not contain advertising functionality.

7. Data Transmission

The App communicates with the GraphQL server configured by the relevant client organisation.

Authentication credentials and application requests are sent to that configured server.

The App does not route ERP requests through a separate publisher-owned application backend.

The client organisation is responsible for the configuration and security of its own server infrastructure.

Important: The production version of the App should be configured to use HTTPS-only connections before making an unconditional statement that all information is encrypted in transit.

8. Third-Party Services

Client Organisation’s GraphQL Server

The App connects to the GraphQL server configured by the client organisation.

This server is required for authentication and App functionality.

The handling, storage and retention of information on that server are governed by the client organisation’s own systems, policies and agreements.

Google Fonts

The current App uses the Inter typeface through the Google Fonts package.

Depending on the App’s final configuration, the font may be requested from Google’s font infrastructure.

The Company may instead bundle the font within the App in a future release to remove this network dependency.

Users should refer to Google’s applicable privacy information for information about Google’s handling of network requests.

9. Data Retention

Information stored locally by the App is retained only as necessary for App functionality and user preferences.

Authentication/session information is cleared when the user signs out.

Business and ERP information displayed by the App is maintained on the client organisation’s server.

The retention period for such information is determined by the relevant client organisation and its applicable policies.

10. Data Security

The App uses security mechanisms including:

  • Secure device storage for authentication/session information.
  • Authentication using access and refresh tokens.
  • Server-side permission checks.
  • Permission-gated access to ERP modules.
  • Authenticated requests to the configured GraphQL server.

The App is designed so that users can access functions according to permissions provided by the client organisation’s server.

No method of electronic transmission or storage can be guaranteed to be completely secure. Users and client organisations are responsible for maintaining appropriate security for their accounts, devices and server infrastructure.

11. User Access and Permissions

The information available to a user depends on the permissions assigned by the user’s client organisation.

The App may hide or restrict modules and actions according to those permissions.

For example, Purchase Order and Quotation Sales approval functions are available only where the relevant server-side permission permits the user to perform those actions.

12. Account Management and Deletion

The App does not provide user account registration.

User accounts are provisioned and managed by the relevant client organisation.

The App currently provides sign-out functionality but does not provide an independent account-deletion function.

If you need your ProfitAcc 365 account or access removed, suspended or modified, you should contact the administrator or authorised representative of your client organisation.

13. Your Privacy Rights

Depending on applicable law, you may have rights regarding personal information, including rights to:

  • Request access to personal information.
  • Request correction of inaccurate information.
  • Request deletion where legally applicable.
  • Request restriction of processing where applicable.
  • Object to certain processing.
  • Request information about how your personal information is handled.

For information controlled by your employer or client organisation, please contact that organisation first.

For information directly handled by the App publisher, you may contact us using the details below.

Privacy Contact: info@numaktech.com

Company: Numak Technology LLC

Address: Al Mulla Plaza , T07 , Al Qusais , Opp.Dubai Police Head Quarters Dubai, UAE.

14. Children’s Privacy

ProfitAcc 365 is a business-oriented ERP application intended for authorised employees and representatives of client organisations.

The App is not designed or marketed as a children’s application.

15. International Data Transfers

The App connects to the server configured by each client organisation.

The location where information is stored or processed may therefore depend on where the client organisation hosts its ERP/GraphQL infrastructure.

Client organisations are responsible for ensuring that their data hosting and transfer arrangements comply with applicable laws and contractual requirements.

16. Contact Us

If you have questions regarding this Privacy Policy or the App’s handling of information, please contact:

Numak Technology LLC

Email: contact@numaktech.com

Address: Al Mulla Plaza , T07 , Al Qusais , Opp.Dubai Police Head Quarters Dubai, UAE.

Website: https://www.profitacc365.com/

Last Updated: 25/09/2026
Chat with Us
Request a Demo

Request a Free Demo

Fill in your details and our ERP expert will contact you shortly.